Registering and using your passkeys
Register, manage, and use your own passkeys at Account → Passkeys. A passkey is a secure credential stored on a device you control, unlocked by a biometric or a device PIN.
What a passkey is
A passkey is a secure credential that lives on a device you control — a laptop, phone, or hardware key — or in a password manager. Each time it is used it must be unlocked with a biometric or a device PIN; possessing the device alone is not enough.
Passkey elevation is not a sign-in method and not login multi-factor authentication. You sign in exactly as you do today, with SSO or a magic link, and the passkey is only ever asked for at the point of a protected action.
Register a passkey
Registering your first passkey is never gated, so anyone can enrol freely — otherwise nobody could ever get started. Nobody is locked out for not having one yet: if you attempt a protected action without a passkey, you are asked to register one there and then.
In Account → Passkeys, start registering a passkey.
Give the passkey a name you will recognise, such as "Work laptop".
Follow your device or password manager's prompt to create it, unlocking with your biometric or device PIN.
The passkey now appears in your list and is ready to use for any protected action.
Remove a passkey
Remove a passkey you no longer use at Account → Passkeys. Removal is scoped to your own credentials, so you can only remove passkeys you registered.
In Account → Passkeys, choose the passkey you want to remove.
Remove it, verifying with a passkey when your organisation protects anything and you already hold one.
What happens when you are asked to verify
You trigger the prompt by performing a protected action, such as approving an access request, changing a team member's role, or revoking an API key. Ploy holds the action and asks you to confirm with a passkey before it completes.
Each verification requires a biometric or a device PIN — having the device in your hand is not enough. You unlock the passkey with your fingerprint, face, or PIN, and the action then goes through.
The verification window
One verification keeps your session elevated for a window that defaults to 15 minutes and can be set anywhere from 1 minute to 8 hours. Repeated protected actions inside that window do not re-prompt you — you verify once and the rest go through until the window ends.
Elevation is per organisation. Verifying in one Ploy organisation does not carry into another, so switching organisations means verifying again there.
Why the prompt reappears
Once the window expires, the next protected action asks you to verify again. You are not locked out and nothing about your sign-in changes — you simply confirm with your passkey once more and the window restarts.
Nobody is blocked for not having a passkey yet. If you attempt a protected action without one, you are asked to register one there and then. Registering your first passkey is never itself gated.
Verifying through Luna
A protected action can never be performed autonomously by Luna. It is held for human confirmation, and the person confirming must have an elevated session. One verification covers confirming a batch of them.
If verification fails
Verification needs the passkey to be available on the current device or in your password manager and unlocked with its biometric or PIN. If it fails, check that the passkey is on this device or in a password manager you can open, and that you are using the correct biometric or PIN.
If you have lost or no longer have access to your passkey, see Passkey elevation troubleshooting and FAQ for how to recover.